Most gaping security holes are terrible mistakes. But for one major Hong Kong-based online retailer called Strawberrynet, its security shortcomings are a feature.
Like many ecommerce sites, registered users have an option for express checkout. What makes beauty-products website Strawberrynet unique is when it comes to security, the site allows you to sign-in to your private account using only your email address. That’s right, no password required.
That sparked the attention of Troy Hunt, who runs the data breach repository HaveIBeenPwned.com. He calls Strawberrynet’s privacy policy “insanity.”
Leave a reply